Anomaly Detection for DNS Servers Using Frequent Host Selection

9 downloads 35197 Views 341KB Size Report
used by various applications such as web and mail transfer. Therefore, monitoring DNS traffic has potential to detect host anomalies such as spammers and ...
2009 International Conference on Advanced Information Networking and Applications

                  ÝÞ    Ý  Þ    Þ    Þ                    Þ    ! " "     #! $ %   & '   !   !      !   Ý



5       *     **               *         (264   "        %, !      +,                 $ " # $   *    7    &    &7      284 .      !   (   " +   ! (  *    !        9$    9*  (  *    !"   *  ! 2:4 2;4 24 2?4 2@4 23A4 !*    ( *      "          .   0           " # $           ! !     !   ,B            " +   !        * ( .    "               ( .     2334 2364"         ! !      $ "           (    .     **  !     !      "  *        !             *  <  " +   ! ! *    3 AAA AAA    (  *   "     !    *   $  , *  (      0(   *"    (  !C  " 6 (*               !"  " 8

    " ! ( "    '  

  %       !      " #!"   '   ") !      !    !    "  !    *% %          " !  '        ! !       '+      "    , '   " !  '+  '           +       ")   !         "   %  ' "-  !    ! !      !      !   " ! . %  !     '   ") " / ! "  '  ! ! !    "  ! !  !        !    %  "" ' "     %  )'     

                           !       " # $ %&' !           !          (" )       !        *  +,    "  -            !       $ ("   .        / *    ! !(  ( -"    *   0   (       ( 0     *   "       (      ! ( "   *        0    ! 0 *  " 1 (  "    0  *  *    ,   234" 1550-445X/09 $25.00 © 2009 IEEE DOI 10.1109/AINA.2009.93

853

      "  " : *               " #  " ;   "

. root

  

(2) .com (3) example.com

   

(1) www.example.com?

                     * (  (    +,    " !    $    !  *         +,     *      (  ( " *         *  ! ½            / +,   D'  D  "          (     * *    "      * * (       *   '  '*     * *   ' * (       ! *"     .   *  *      ! *"   6    *C     *     *"    .     * !         ( /  !"    *       / .      * *     !    '   '*    $" 5         * * (      *             *" #(" 3      .    *(  +,       " )   .     *     E!!!"$"  F 3  * .     * *     / .   * 6 8 :      !   ! ;" 0    * .    E"F     * *    E F  E$F    * *  * " +       * *  E$" F       E!!!"$" F   E3@6"3

Suggest Documents